
User Manual
3onedata proprietary and confidential
Copyright © 3onedata Co., Ltd.
32
Client
The management client for which the configuration below applies.
Method
Method can be set to one of the following values:
No: Authentication is disabled and login is not possible.
Local: Use the local user database on the switch for authentication.
radius: Use one or more of the remote RADIUS servers for authentication.
tacacs: Use one or more of the remote servers for authorization.
Methods that involves remote servers are timed out if the remote servers are offline.
In this case the next method is tried. Each method is tried from left to right and
continues until a method either approves or rejects a user. If a remote server is used
for primary authentication it is recommended to configure secondary authentication as
local. This will enable the management client to log in via the local user database if
none of the configured authentication servers are alive.
4.3.2 Command Authorization Method Configuration
The command authorization section allows you to limit the CLI commands available to
a user. The table has one row for each client type and a number of columns which are
as follows:
Client
The management client for which the configuration below applies.
Method
It can be set to one of the following values:
no: Command authorization is disabled. User is granted access to CLI commands
according to his privilege level.
tacacs: Use one or more of the remote servers for command
authorization. If all remote servers are offline, the user is granted access to CLI
commands according to his privilege level.
Cmd Lvl
Authorizes all commands with a privilege level higher than or equal to this level. Valid
values are in the range 0 to 15.